dragnucs

joined 3 years ago
[–] dragnucs@lemmy.ml 3 points 4 months ago (2 children)

It is good you have solved you initial issue. However, as you say, your rules are too permissive. You should not publish ports from containers to the host. Your container ports should only be accessible over reverse-proxy network. Said otherwise :3000 should not resolve to anything.

This can be simply acheive by not publishing any port on your service containers.

Here is an example of my VPS:

Exposed ports:

$ ss -ntlp
State                Recv-Q               Send-Q                             Local Address:Port                             Peer Address:Port              Process                                                  
LISTEN               0                    128                                      0.0.0.0:22                                    0.0.0.0:*                  users:(("sshd",pid=4084094,fd=3))                       
LISTEN               0                    4096                                     0.0.0.0:443                                   0.0.0.0:*                  users:(("conmon",pid=3436659,fd=6))                     
LISTEN               0                    4096                                     0.0.0.0:5355                                  0.0.0.0:*                  users:(("systemd-resolve",pid=723,fd=11))               
LISTEN               0                    4096                                     0.0.0.0:80                                    0.0.0.0:*                  users:(("conmon",pid=3436659,fd=5))                     
LISTEN               0                    4096                                  127.0.0.54:53                                    0.0.0.0:*                  users:(("systemd-resolve",pid=723,fd=19))               
LISTEN               0                    4096                               127.0.0.53%lo:53                                    0.0.0.0:*                  users:(("systemd-resolve",pid=723,fd=17))  

Redacted list of containers:

$ podman container ls
CONTAINER ID  IMAGE                                        COMMAND               CREATED        STATUS                 PORTS                                     NAMES
[...]
docker.io/tootsuite/mastodon-streaming:v4.3  node ./streaming      2 months ago   Up 2 months (healthy)                                            social_streaming
docker.io/eqalpha/keydb:alpine               keydb-server /etc...  2 months ago   Up 2 months (healthy)                                            cloud_cache
localhost/podman-pause:4.4.1-1111111111                            2 months ago   Up 2 months            0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp  1111111111-infra
docker.io/library/traefik:3.2                traefik               2 months ago   Up 2 months            0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp  traefik
docker.io/library/nginx:1.27-alpine          nginx -g daemon o...  3 weeks ago    Up 3 weeks                                                       cloud_web
docker.io/library/nginx:1.27-alpine          nginx -g daemon o...  3 weeks ago    Up 3 weeks                                                       social_front
[...]
[–] dragnucs@lemmy.ml 2 points 4 months ago* (last edited 4 months ago)

You can use a black theme. Look at gnome-look.org

You can also reverse engineer them to look how they make the theme blank and apply it to adwaita. This is not complicated as themes are mostly CSS.

Edit to add that you can chat with people from open deskttop (gnome look) to ask your question: https://chat.opendesktop.org/#/welcome

[–] dragnucs@lemmy.ml 2 points 4 months ago* (last edited 4 months ago)

@noclue I guess the dress is just three hundred fifty five dollars.

[–] dragnucs@lemmy.ml 0 points 4 months ago* (last edited 4 months ago)

I guess they say $335,000 with a coma si it is just three hunder thirty five dollars while the interest rate is 6.95% with a dot so it is almost a seven?

[–] dragnucs@lemmy.ml 3 points 4 months ago (3 children)

Why should the drives be sneakily deposited. If he trusts his relative or friend he may just tell them to keep it safe until new gets out.

However the bigger challenge would be to read the files using newer technology since those drive connectors might get obsolete. Maybe you need to store technology you can read it with. For example an external disk drive with USB 3 cables and Somme USB C adapters. If using internal drives this gets a bit complicated since you would need also some cables and motherboards. So external hard drives would be easier.

[–] dragnucs@lemmy.ml 6 points 4 months ago* (last edited 4 months ago) (1 children)

Maybe you could delete Reddit. But you can self-host your own lemmy instance in addition to you website. It does not hurt to have your own website in addition to social media.

However, you cannot host a lemmy on github pages.

[–] dragnucs@lemmy.ml 6 points 4 months ago

They have potential. They always endup being used. Sometimes, to make better use of space I might swap bigger jars with smaller ones depending on the content. In the storage cabinet, bigger jars can contain smaller ones.

[–] dragnucs@lemmy.ml 1 points 5 months ago

How can it be both a marathon and a gamble?

[–] dragnucs@lemmy.ml 1 points 5 months ago

Fixed. Thanks.

[–] dragnucs@lemmy.ml 14 points 5 months ago* (last edited 5 months ago) (7 children)

You should try Thunder. It is available on Izzysoft. Its is FOSS (AGPL) but I don't know why it is not in official f-droid repository.

[–] dragnucs@lemmy.ml 5 points 5 months ago (1 children)

Seems like you have a permissions issue. I just tested it on Fedora workstation gnome, run it from regular menu, then it asked me for password. You, you have a permission denied isssue, so you need to figure out how to run it as root.

[–] dragnucs@lemmy.ml 3 points 5 months ago (1 children)

Literally a barn owl.

 
 
 
19
Hot dog (lemmy.ml)
 
 
 

So I have this exact need:

There is an upstream project doing their own thing over git and I want to build container images locally and commit them to my image repository all while following the same version system as upstream.

To be more precise (perhaps abstract) about my need, what is the best way to apply the same patch when upstream release a new version.

Any input and best practices or lessons learned are welcome.

 
 

Is there any FOSS to manage subscriptions? My particular need is to trigger an API call upon subscription to start the service, and then bill subscribers based on their usage. The service would report the usage to the subscription manager.

It would be awesome if the manager also provides a user area for subscribers to manage their subscription, pay bills and change a few settings, create support tickets, etc.

Duplicate of https://lemmy.ml/post/92688 since I am not sure this kind crossposts are allowed.

 

Is there any FOSS to manage subscriptions? My particular need is to trigger an API call upon subscription to start the service, and then bill subscribers based on their usage. The service would report the usage to the subscription manager.

It would be awesome if the manager also provides a user area for subscribers to manage their subscription, pay bills and change a few settings, create support tickets, etc.

3
Join. (lemmy.ml)
 
 

I am looking for sublemmies I could follow that have no other target than entertainment, like eyebleach, PIC, hummm, dank memes, advice animals, battle station, amateurroomporn, natureismetal, pics of unusual birds, etc. Just nice, interesting and funny thinks to look at or read.

Having a feed fool of !privacy posts is quit depressing.

view more: ‹ prev next ›